Tenable announced on 3 September, at OpenAI's Intelligence at Work Cyber Summit, that it is building the CyberAgents Exchange AI Inspector with OpenAI: a security review that runs community submitted AI agents, skills, MCP servers and multi agent playbooks through OpenAI's GPT cyber models, through Tenable's own exposure scanning, and past human researchers before enterprises deploy them.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source 2 GlobeNewswire 2026-09-03 Wire copy of the release confirming components, process, timing and background. Open source The registry it guards, the CyberAgents Exchange, launched in August as an open source cybersecurity native catalog and holds more than 100 components after a build event at Black Hat USA.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source 3 Taiwan News 2026-09-04 Registry address exchange.tenable.com; syndicated confirmation of the three step process. Open source The Inspector is expected to be available in September.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source Our assessment, with high confidence, is that this is the first serious attempt to put an app store style gate on the agent supply chain; with moderate confidence, that the gate will matter far more for MCP servers and skills, which execute with real permissions, than for the agents themselves; and with moderate confidence that the market's flat reaction, shares down 0.70 percent, reflects a product that is early rather than one that is unimportant.4 Stock Titan 2026-09-04 TENB down 0.70 percent on 4 September; up 2.77 percent on the 4 August Exchange launch; restated product facts. Open source

The problem being solved

Enterprise agent deployments are assembled from parts nobody in the enterprise wrote. A skill is a folder of instructions and scripts an agent loads; an MCP server is a process that gives the agent tools, often with credentials; a playbook wires several agents together. All of these are increasingly downloaded from community registries, and a malicious or merely careless one runs with whatever access the agent has. This is the software supply chain problem transposed to a new artifact type, with the added twist that the artifact is partly natural language and partly code, and static analysis tools built for code do not read the language half.

Tenable's registry already exists to collect these components; the Inspector is the review layer.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source The three elements are a frontier assessment using OpenAI's cyber tuned models, which can read both the prose and the code; a skills inspection powered by Tenable One AI Exposure, the company's existing exposure management product; and expert review by Tenable researchers.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source 3 Taiwan News 2026-09-04 Registry address exchange.tenable.com; syndicated confirmation of the three step process. Open source Chief product officer Eric Doerr's framing, that agentic AI will only reach its potential in the enterprise if security teams can trust the components introduced into their environments, is the pitch.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source

Why OpenAI is in it

The collaboration grew from Tenable's participation in OpenAI's Daybreak Defense Network, the program through which OpenAI gives vetted defenders access to its restricted cyber capable models.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source 2 GlobeNewswire 2026-09-03 Wire copy of the release confirming components, process, timing and background. Open source That is the same gating mechanism that surrounds GPT-6 Astra's offensive capabilities, turned toward defense: a model that can find vulnerabilities in code can find them in an agent skill before it ships. For OpenAI, Exchange Inspector is a public use case for models it otherwise keeps behind a program, and a demonstration that the Critical cyber rating on its frontier model has a defensive dividend.

The registry lives at exchange.tenable.com and is open source, which means the components are public and so, presumably, will be the inspection results.3 Taiwan News 2026-09-04 Registry address exchange.tenable.com; syndicated confirmation of the three step process. Open source A public review of a public component is a stronger signal than a private scan, because the community can check the checker.

Who gains and who loses

Enterprise security teams gain a filter for a category of software they currently cannot evaluate, assuming the Inspector's output is usable in their existing tooling.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source Component authors who pass gain a badge that distinguishes them from the unvetted majority. Tenable gains a position at the head of a supply chain that did not exist a year ago, and a story that connects its exposure management franchise to agents.4 Stock Titan 2026-09-04 TENB down 0.70 percent on 4 September; up 2.77 percent on the 4 August Exchange launch; restated product facts. Open source OpenAI gains a defensive showcase for its cyber models.

Registries without a review layer lose relative standing; if inspected becomes the expectation, an uninspected catalog is a liability. Component authors who fail, or who are never reviewed because the researchers are a bottleneck, lose distribution. And the companies whose agents run uninspected MCP servers today lose the excuse that there was no way to check.

The counter case

The Inspector reviews 100 components with a process that includes human researchers, which does not scale to the thousands of skills and servers already circulating outside Tenable's registry.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source If the review is thorough it is slow, and if it is fast it is mostly the model, whose false positive and false negative rates on this artifact type are unknown. A badge from one vendor's registry also does not travel: an enterprise pulling a skill from GitHub gets no benefit unless the Inspector's checks are published as a standard others can run. The market's reaction, a small decline after the announcement against a rise for the registry launch a month earlier, suggests investors see the Inspector as a feature of an existing product rather than a new line.4 Stock Titan 2026-09-04 TENB down 0.70 percent on 4 September; up 2.77 percent on the 4 August Exchange launch; restated product facts. Open source Finally, the artifact is not yet shipping; September availability is a plan.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source

What to watch

  • Inspector ships in September. Public availability by 30 September with published results on the existing 100 plus components would confirm the plan; a slip would suggest the researcher review is the constraint.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source
  • Published inspection criteria. A specification of what the frontier assessment and the Tenable One scan check, released within three months, would let other registries adopt it and turn a product into a standard.3 Taiwan News 2026-09-04 Registry address exchange.tenable.com; syndicated confirmation of the three step process. Open source
  • A caught malicious component. A documented case of the Inspector rejecting a skill or MCP server for a real security flaw within six months would be the proof of value; none would leave the exercise theoretical.1 Tenable 2026-09-03 Exchange Inspector: frontier assessment with GPT cyber models, Tenable One AI Exposure skills inspection, researcher review; expected September 2026; Exchange launched August 2026 with 100 plus components after SWARM at Black Hat; Daybreak Defense Network origin; Cyber Summit venue; Doerr quote. Open source
  • A rival registry adds review. Any other agent or MCP catalog announcing a security review layer by early 2027 would confirm inspection has become table stakes.2 GlobeNewswire 2026-09-03 Wire copy of the release confirming components, process, timing and background. Open source

The agent ecosystem has an app store with no review team. Tenable and OpenAI are the first to hire one, for one store, and the question is whether the rest of the ecosystem follows or routes around it.